Complete index
Zero-Day Vulnerability Archive
Search all tracked zero-day vulnerabilities and narrow the results by year, vendor, software, weakness type, or presence in the CISA and ENISA known exploited vulnerability catalogs.
| CVE | Vendor / Product | Vulnerability | CWE | Discovered | KEV |
|---|---|---|---|---|---|
| CVE-2020-3566 | Cisco Systems, IncCisco IOS XR | Resource exhaustion in Cisco IOS XR and Cisco ASR 9000 Series Aggregation Services Routers | CWE-400 | CISA KEVENISA KEV | |
| CVE-2020-1380 | MicrosoftMicrosoft Internet Explorer | Buffer overflow in Microsoft Internet Explorer | CWE-119 | CISA KEVENISA KEV | |
| CVE-2020-1464 | MicrosoftMicrosoft Windows | Cryptographic issues in Microsoft Windows and Windows Server | CWE-310 | CISA KEVENISA KEV | |
| CVE-2022-38028 | MicrosoftMicrosoft Windows | Permissions, Privileges, and Access Controls in Microsoft Windows and Windows Server | CWE-264 | CISA KEVENISA KEV | |
| #VU27929 | XootiXLogin/Signup Popup ( Inline Form + Woocommerce ) | Stored cross-site scripting in Login/Signup Popup ( Inline Form + Woocommerce ) | CWE-79 | — | |
| #VU27672 | ElementorElementor Pro | Arbitrary file upload in Elementor Pro | CWE-434 | — | |
| CVE-2020-12271 | SophosSophos Firewall | SQL injection in Sophos Firewall | CWE-89 | CISA KEVENISA KEV | |
| #VU27193 | Apple Inc.Apple iOS | Out-of-bounds write in Apple iOS | CWE-787 | — | |
| CVE-2020-1027 | MicrosoftMicrosoft Windows | Buffer overflow in Microsoft Windows and Windows Server | CWE-119 | CISA KEVENISA KEV | |
| CVE-2020-6820 | MozillaMozilla Firefox | Use-after-free in Firefox ESR and Mozilla Firefox | CWE-416 | CISA KEVENISA KEV | |
| CVE-2020-6819 | MozillaMozilla Firefox | Use-after-free in Firefox ESR and Mozilla Firefox | CWE-416 | CISA KEVENISA KEV | |
| CVE-2020-0938 | MicrosoftMicrosoft Windows | Buffer overflow in Microsoft Windows and Windows Server | CWE-119 | CISA KEVENISA KEV | |
| CVE-2020-1020 | MicrosoftMicrosoft Windows | Buffer overflow in Microsoft Windows and Windows Server | CWE-119 | CISA KEVENISA KEV | |
| #VU26285 | Merit LILIN Ent. Co., Ltd.DHD204, DHD204A, DHD208, DHD208A, DHD216, DHD216A, DHD304A, DHD308A, DHD316A, DHD504A, DHD508A, DHD516A | Use of hard-coded credentials in Merit LILIN Ent. Co., Ltd. products | CWE-798 | — | |
| CVE-2020-8468 | Trend MicroApex One | Input validation error in Trend Micro products | CWE-20 | CISA KEVENISA KEV | |
| CVE-2020-8467 | Trend MicroOfficeScan | Code Injection in OfficeScan and Apex One | CWE-94 | CISA KEVENISA KEV | |
| #VU25822 | Unknown | Improper access control in Custom Searchable Data Entry System | CWE-284 | — | |
| #VU25677 | Unknown | Stored cross-site scripting in Async JavaScript | CWE-79 | — | |
| #VU25676 | Unknown | Stored cross-site scripting in 10Web Google Maps - Google Maps builder Plugin | CWE-79 | — | |
| #VU25675 | Unknown | Stored cross-site scripting in Modern Events Calendar Lite | CWE-79 | — |
Showing 541–560 of 1,000 results